Symantec and Carbon Black researchers have discovered a stealthy new infostealer named Speagle.
This malware hijacks Cobra DocGuard, a legitimate document security platform developed by the Chinese company EsafeNet, to surreptitiously harvest and exfiltrate sensitive data.
By communicating with a compromised Cobra DocGuard server, Speagle masks its data theft as legitimate network traffic.
Notably, specific variants of this malware are highly targeted, explicitly searching infected machines for documents related to Chinese ballistic missiles.
Technical Execution and Data Collection
Speagle is a 32-bit .NET executable that initiates its attack by locating the Cobra DocGuard installation directory through specific registry keys or a hardcoded path.
Once established, the malware executes its data collection in three distinct phases, attempting to exfiltrate data after each step to ensure partial success even if interrupted.
In the first phase, Speagle gathers basic system details, such as the Windows user name, host name, and specific client identification tokens, from Cobra DocGuard configuration files.
To exfiltrate this stolen information, the malware serializes the data into an XML structure, compresses it using the Deflate algorithm, and encrypts it with AES-128 in CBC mode.
The encrypted data is then sent via HTTP POST requests to a compromised Cobra DocGuard server hosted by the targeted organization, effectively blending in with normal network operations.
During the second phase, Speagle expands its collection by executing Windows Management Instrumentation queries to map out the system environment, including network configurations, running processes, and attached drives.

It recursively scans local and network drives, specifically targeting user directories to compile lists of file names and sizes.
In the third phase, the malware targets web browser data by searching the application data directory for SQLite databases associated with browser history, autofill information, downloads, and bookmarks.
The malware extracts this sensitive information into its custom data structure for transmission. One specific variant of Speagle goes further by actively searching for targeted keywords related to aerospace, composite materials, and Dongfeng ballistic missiles.
Supply Chain Threat and Evasion Tactics
The exact initial vector of infection for Speagle remains unconfirmed. However, researchers suspect it may be distributed via a supply-chain attack.
The malware relies heavily on security Cobra DocGuard infrastructure, including its self-deletion driver and command-and-control servers, strongly suggesting the threat could have been delivered as a trojanized software update.
Cobra DocGuard has a history of being exploited in supply chain attacks, notably by advanced persistent threat groups like Carderbee in 2022 and 2023.
Currently tracked under the moniker Runningcrab, the threat actors behind Speagle demonstrate deliberate targeting, pointing toward either state-sponsored industrial espionage or a highly sophisticated private contractor.
Follow us on Google News , LinkedIn and X to Get More Instant Updates. Set Cyberpress as a Preferred Source in Google.